Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.

Project Subscriptions

Vendors Products
Debian Linux Subscribe
Fedoraproject Subscribe
Opensuse Subscribe
Opensuse Subscribe
Enterprise Linux Subscribe
Enterprise Linux Desktop Subscribe
Enterprise Linux Server Aus Subscribe
Enterprise Linux Server Eus Subscribe
Enterprise Linux Workstation Subscribe
Gluster Storage Subscribe
Storage Subscribe
Storage For Public Cloud Subscribe
Advisories
Source ID Title
Debian DSA Debian DSA DSA-2439-1 libpng security update
EUVD EUVD EUVD-2011-3013 Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.
Ubuntu USN Ubuntu USN USN-1402-1 libpng vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
Link Providers
http://code.google.com/p/chromium/issues/detail?id=116162 cve-icon cve-icon
http://googlechromereleases.blogspot.com/2012/03/stable-channel-update_21.html cve-icon cve-icon
http://libpng.git.sourceforge.net/git/gitweb.cgi?p=libpng/libpng%3Ba=commit%3Bh=a8c319a2b281af68f7ca0e2f9a28ca57b44ceb2b cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2012-March/075424.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2012-March/075619.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2012-March/075981.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2012-March/075987.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2012-March/076461.html cve-icon cve-icon
http://lists.fedoraproject.org/pipermail/package-announce/2012-March/076731.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-security-announce/2012-04/msg00000.html cve-icon cve-icon
http://lists.opensuse.org/opensuse-updates/2012-03/msg00051.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2012-0407.html cve-icon cve-icon
http://rhn.redhat.com/errata/RHSA-2012-0488.html cve-icon cve-icon
http://secunia.com/advisories/48320 cve-icon cve-icon
http://secunia.com/advisories/48485 cve-icon cve-icon
http://secunia.com/advisories/48512 cve-icon cve-icon
http://secunia.com/advisories/48554 cve-icon cve-icon
http://secunia.com/advisories/49660 cve-icon cve-icon
http://security.gentoo.org/glsa/glsa-201206-15.xml cve-icon cve-icon
http://src.chromium.org/viewvc/chrome?view=rev&revision=125311 cve-icon cve-icon
http://www.debian.org/security/2012/dsa-2439 cve-icon cve-icon
http://www.mandriva.com/security/advisories?name=MDVSA-2012:033 cve-icon cve-icon
http://www.securitytracker.com/id?1026823 cve-icon cve-icon
https://bugzilla.redhat.com/show_bug.cgi?id=799000 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2011-3045 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14763 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2011-3045 cve-icon
History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.04701}

epss

{'score': 0.05814}


Mon, 09 Jun 2025 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-195
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-06-09T15:35:52.219Z

Reserved: 2011-08-09T00:00:00.000Z

Link: CVE-2011-3045

cve-icon Vulnrichment

Updated: 2024-08-06T23:22:27.386Z

cve-icon NVD

Status : Deferred

Published: 2012-03-22T16:55:01.160

Modified: 2025-06-09T16:15:22.810

Link: CVE-2011-3045

cve-icon Redhat

Severity : Moderate

Publid Date: 2012-03-08T00:00:00Z

Links: CVE-2011-3045 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses